Skill Audit by Raini

# Skill Audit ๐Ÿ”

Safety Notice

This listing is from the official public ClawHub registry. Review SKILL.md and referenced scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "Skill Audit by Raini" with this command: npx skills add raini-skill-audit

Skill Audit ๐Ÿ”

ๆ‰ซๆ OpenClaw skills ไธญ็š„ๅฎ‰ๅ…จ้ฃŽ้™ฉ๏ผŒ้˜ฒๆญขไพ›ๅบ”้“พๆ”ปๅ‡ปใ€‚


ๆŒ‡ไปค

/skill-audit scan [skill-name]

ๆ‰ซๆๅทฒๅฎ‰่ฃ…็š„ skill๏ผŒๆฃ€ๆต‹ๅฏ็–‘ไปฃ็ ๆจกๅผใ€‚

# ๆ‰ซๆๆ‰€ๆœ‰ๅทฒๅฎ‰่ฃ… skill
skill-audit scan

# ๆ‰ซๆๆŒ‡ๅฎš skill
skill-audit scan moltdash

# ๆ‰ซๆๆœฌๅœฐ็›ฎๅฝ•
skill-audit scan ./my-skill

/skill-audit check <clawhub-slug>

ๅฎ‰่ฃ…ๅ‰ๆฃ€ๆŸฅ ClawHub ไธŠ็š„ skillใ€‚

skill-audit check some-skill

ๆฃ€ๆต‹่ง„ๅˆ™

๐Ÿ”ด ้ซ˜้ฃŽ้™ฉ (Critical)

  • ่ฏปๅ–ๅ‡ญ่ฏๆ–‡ไปถ: ~/.ssh/, ~/.env, credentials.json
  • ๅค–ๅ‘ๆ•ฐๆฎ: fetch(), curl, webhook, POST ๅˆฐๆœช็Ÿฅ URL
  • ไปฃ็ ๆ‰ง่กŒ: eval(), exec(), child_process
  • ่ฏปๅ–็Žฏๅขƒๅ˜้‡ไธญ็š„ๅฏ†้’ฅ: process.env.API_KEY

๐ŸŸ  ไธญ้ฃŽ้™ฉ (Warning)

  • ็ฝ‘็ปœ่ฏทๆฑ‚ๅˆฐ้ž็ŸฅๅๅŸŸๅ
  • ๆ–‡ไปถ็ณป็ปŸ้ๅކ: fs.readdir(), glob
  • ๅŠจๆ€ require/import
  • Base64 ็ผ–็ ็š„ๅญ—็ฌฆไธฒ (ๅฏ่ƒฝๆ˜ฏๆททๆท†)

๐ŸŸก ไฝŽ้ฃŽ้™ฉ (Info)

  • ไฝฟ็”จ shell ๅ‘ฝไปค
  • ่ฏปๅ†™็”จๆˆท็›ฎๅฝ•ๅค–็š„ๆ–‡ไปถ
  • ๅคง้‡ไพ่ต–ๅŒ…

่พ“ๅ‡บ็คบไพ‹

๐Ÿ” Skill Audit Report: suspicious-weather
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Risk Score: 85/100 ๐Ÿ”ด HIGH RISK

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ File        โ”‚ Severity โ”‚ Finding                         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ Reads ~/.openclaw/credentials/  โ”‚
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ POST to webhook.site            โ”‚
โ”‚ utils.ts    โ”‚ WARNING  โ”‚ Uses eval()                     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โš ๏ธ  DO NOT INSTALL - This skill may steal your credentials!

่ฟ่กŒๆ–นๅผ

่ฏฅ skill ้™„ๅธฆไธ€ไธช CLI ่„šๆœฌ๏ผŒagent ๅฏ็›ดๆŽฅ่ฐƒ็”จ๏ผš

node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all

ๅ‚่€ƒ

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

aig-scanner

Comprehensive OpenClaw security scanning powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). Use when the user asks to start a security health check or sec...

Registry SourceRecently Updated
Security

Dataset Intake Auditor

ๅœจๆ–ฐๆ•ฐๆฎ้›†ๆŽฅๅ…ฅๅ‰ๆฃ€ๆŸฅๅญ—ๆฎตใ€ๅ•ไฝใ€็ผบๅคฑ็އใ€ๅผ‚ๅธธๅ€ผไธŽๅฏ็”จๆ€งใ€‚๏ผ›use for data, dataset, audit workflows๏ผ›do not use for ไผช้€ ็ปŸ่ฎก็ป“ๆžœ, ๆ›ฟไปฃๆญฃๅผๆ•ฐๆฎๆฒป็†ๅนณๅฐ.

Registry SourceRecently Updated
02
Profile unavailable
Security

Session Password

Provides secure session authentication using bcrypt-hashed passwords, security questions, email recovery, and lockout protection with audit logging.

Registry SourceRecently Updated
118
Profile unavailable